Haystack
← Back to Jobs
Remote
Technology
NG

Senior Information Security Analyst (Governance, Risk & Compliance) - W2 Role ( Remote)

NGTalentTech Group LLCUnited States🇺🇸United StatesPosted Sep 29, 2026

Quick Overview

Seniority
Mid Senior
Work mode
Remote
Location
United States
Posted
Yesterday
OWASPSOC 2HIPAA

Job Description

Job Title: Senior Information Security Analyst (Governance, Risk & Compliance)

Remote position

W2 Requirement

Role Overview

Track and coordinate the work behind the HIPAA Security Risk Analysis and SOC 2 readiness, and support third-party risk, data inventory, and broader compliance programs. Identify and document gaps, then work with the business to drive remediation to closure.

Responsibilities

- *HIPAA Security Risk Analysis:* Support the annual SRA alongside an external assessor.

  - Confirm scope covers every system that handles ePHI.

  - Coordinate evidence and subject matter expert interviews.

  - Track findings, corrective actions, and exceptions through to closure.

- *SOC 2:* Support readiness and audits through Type 1, Type 2, and ongoing annual cycles.

  - Gap assessments against the Trust Services Criteria.

  - Auditor requests and evidence collection.

  - Control narratives and exception tracking.

  - Monitoring controls between audits.

- *Remediation tracking:* Own the record for each gap (owner, due date, status, evidence), run check-ins with the teams doing the work, and report progress to leadership.

- *Control mapping:* Map controls across HIPAA, SOC 2, and NIST CSF 2.0 so evidence can be reused across frameworks, laying the groundwork for HITRUST.

- *Secondary focus:*

  - Coordinate data, technology, and AI inventories, including where PHI lives, who owns it, and how it's classified.

  - Support third-party risk management:

    - Classify vendors by risk tier.

    - Review SOC reports and security questionnaires.

    - Research vendor risk signals.

    - Coordinate BAAs, NDAs, and MSAs with Legal.

    - Keep vendor onboarding, offboarding, and risk records audit-ready.

  - Maintain the security risk register and risk acceptances, and act as liaison to the enterprise risk management program.

  - Produce regular security metrics and status reporting, and coordinate evidence for periodic user access reviews.

  - Help maintain security policies and procedures, handle first-pass intake for security reviews and RFP security requirements, and support customer security questionnaires.

  - Keep records of approved AI tools and use cases current.

Qualifications

- 4+ years in security compliance, GRC, risk management, or audit, ideally in healthcare or another highly regulated industry.

- Direct experience supporting SOC 2 audits and HIPAA risk analyses with external auditors or assessors.

- Working knowledge of the HIPAA Security Rule and how PHI moves through cloud and SaaS environments.

- Hands-on experience with at least one GRC or compliance automation platform.

- Strong project coordination skills across multiple teams.

- Day-to-day proficiency using AI tools to streamline compliance work.

- Strong written and verbal communication skills.

*Extra Credit:*

- Familiarity with NIST AI RMF, OWASP SAMM, or HITRUST.

- Vendor security review or third-party risk experience.

- Experience on a small, high-performing team.

- Interest in growing toward security engineering or governance leadership.

- CISA, CRISC, or CISSP (not required).

Similar jobs